What you will set up
DirectAdmin is a control panel: from your browser, you create websites, install WordPress, manage mail and databases, and get free certificates, without the command line.
Like Plesk, DirectAdmin takes over the whole server and installs its own web, mail and DNS servers, so it needs a server of its own, freshly installed, and it runs as root. It needs a licence from DirectAdmin before you install it.
Every step below was run on a fresh Melonslab VC-P Alloy (2 vCPU, 8 GB) with Debian 13:
- DirectAdmin 1.711 installed in about 25 minutes, with Apache, PHP 8.3, MariaDB 10.11, Exim, Dovecot, Pure-FTPd, BIND and the CSF firewall, and got a Let's Encrypt certificate for its own address by itself.
- A website got its own certificate within a minute of being created, and answered on both the server's IPv4 and IPv6 address once the IPv6 address was linked (step 4). WordPress was installed on it.
- The firewall blocked a port it had no rule for, and the DNS server refused to look up other domains for anyone on the internet.
- A message from a mailbox on the site passed SPF, reverse DNS and DKIM at an external checker, and its reply arrived in the mailbox. In Exim's test mode, an attempt to relay mail from an outside address was refused.
- A backup of every account took under a minute, and everything came back by itself after a reboot.
With one WordPress site, the server used about 1.1 GB of memory.
Before you start
You need:
- a DirectAdmin licence key. DirectAdmin sells licences on directadmin.com, from $5 a month for 2 accounts, and has no free trial;
- a fresh Melonslab server with Debian 13 and nothing else installed, with at least 4 GB of memory;
- swap: DirectAdmin asks for 4 GB of it. Leave swap disabled when you build the server in the Melonslab panel, and set up swap in memory with the zram guide first;
- a name for the server, such as
da.example.com, with an A record and an AAAA record pointing at it; - reverse DNS for both of the server's addresses set to that name, if the server will send mail (step 7), as in step 2 of the Postfix guide.
Set up SSH keys and automatic security updates as in steps 1 to 3 of the security guide, and skip its step 4: DirectAdmin installs its own firewall.
The examples use da.example.com for the server and example.com for a website. Replace them with your own throughout.
1. Name the server
DirectAdmin uses the server's name for its own address and its certificate. As root:
hostnamectl set-hostname da.example.com
hostname -f
The last command prints da.example.com.
2. Install DirectAdmin
Put your licence key between the quotes, and your own email address after DA_EMAIL. DirectAdmin sends notices about the server there.
apt update
apt install -y curl
DA_HOSTNAME=da.example.com DA_EMAIL=you@example.com bash <(curl -fsSL https://download.directadmin.com/setup.sh) 'YOUR-LICENCE-KEY'
This is DirectAdmin's own installer, with its default choices. After about a minute, it prints the admin user name, admin, its password and a login link. The link logs you in once, so keep it to yourself. The password is also saved in /usr/local/directadmin/conf/setup.txt, and da login-url makes a new link.
DirectAdmin then keeps installing the web, mail and database servers in the background, which took about 25 minutes on our test server. When it is done, a message called CustomBuild installation has finished appears under Messages in the panel.
3. Log in
Open the link, or go to https://da.example.com:2222 and log in as admin. The Admin and User tabs above the menu switch between managing the server and managing the admin's own websites. The steps below say which one to use.
4. Give websites IPv6 too
DirectAdmin registers only the server's IPv4 address. Every Melonslab server has IPv6, so add the IPv6 address and link it to the IPv4 address. On the Admin tab:
- Open Server Manager, then IP Management, and choose Add IP.
- Choose IPv6, and enter the server's IPv6 address from the client area. The netmask changes to
/64by itself. - Untick Add to device, because the address is already on the server, and choose Add IP.
- Choose the IPv4 address in the list, then Link IP. Pick the IPv6 address, keep Add to DNS, Add to Apache and Apply to existing domains ticked, and choose Link.
Every website on the IPv4 address now answers on the IPv6 address too, and DirectAdmin adds AAAA records to the DNS zones it manages.
5. Create a package and a user
In DirectAdmin, every website belongs to a user account, and every account gets its limits from a package. On the Admin tab, under Account Manager:
- Open Manage User Packages, and choose Add Package. Set the limits, such as Disk Space (MB). Keep PHP Access and SSL Access ticked, and tick WordPress, which is off by default. Enter a Package Name, such as
basic, and choose Save. - Open Add New User. Enter a Username, such as
anna, an E-mail address, a Password and the website's Domain,example.com, pick the package, and choose Submit. Send E-mail Notification sends the login details to that address.
6. Add the website
First, point the domain at your server where its DNS is managed: an A record and an AAAA record for example.com, and the same for www.example.com. When the records are in place before you create the user, DirectAdmin gets a Let's Encrypt certificate for both names by itself within a minute, and renews it by itself. Otherwise, request one under Account Manager and SSL/TLS Certificates.
Log in as the user, anna, at https://da.example.com:2222. To send visitors from HTTP to HTTPS, open Account Manager, then Domains, and choose the domain. Tick Force SSL with https redirect, and choose Modify.
Put your files in the site's public_html folder, under domains/example.com, from System Info & Files and File Manager, or over FTP.
For WordPress, open Advanced Features and then WordPress Manager, and choose Install next to the domain. Enter a Title, and turn on Advanced mode to choose the admin email address, user name and password yourself. Choose Create, then Confirm to let it replace the placeholder page. The installer shows the login address, https://example.com/wp-admin, when it is done.
7. Set up mail
Port 25 is open on every Melonslab server from the first boot. Check that reverse DNS for both addresses is set to da.example.com, then, as the user:
- Use the mailbox, or add more. DirectAdmin creates a mailbox with the user's name and password, such as
anna@example.com. Add more under E-mail Manager, E-mail Accounts, Create Account. - Turn on DKIM. On the same page, choose Enable DKIM. DirectAdmin signs outgoing mail from then on.
- Publish the DNS records. DirectAdmin creates them in its own DNS zone for the domain, under Account Manager and DNS Management. If your domain's DNS is managed elsewhere, create them there: an MX record for
example.compointing atda.example.com, the SPF record (the TXT record onexample.com), the DKIM key (the TXT record atx._domainkey.example.com), and a DMARC record at_dmarc.example.com, such asv=DMARC1; p=none. Copy the SPF and DKIM values from DNS Management. Without the DKIM record, every signature fails at the receiving end, which is worse than no signature at all.
In mail apps, use da.example.com as the server, which is the name on the certificate, with the full address, anna@example.com, as the user name:
| Server | Port | Security | |
|---|---|---|---|
| Incoming (IMAP) | da.example.com | 993 | SSL/TLS |
| Outgoing (SMTP) | da.example.com | 465 | SSL/TLS |
Webmail is under Extra Features and Webmail: Roundcube. To check the setup, send a message to check-auth@verifier.port25.com. Its report arrives within a minute and should show SPF check: pass, "iprev" check: pass and DKIM check: pass.
These steps are for your own mail, your company's mail and mail from your websites. Newsletters and other high-volume sending need an arrangement with our sales team first.
8. Keep it up to date
DirectAdmin updates itself. The web, mail and database servers it installed are updated by its CustomBuild tool, which you can let do that by itself. As root:
da build set updates yes
da build set webapps_updates yes
da build cron
The last command shows Automatic updates: yes, checked daily. To update by hand instead, run da build update_versions. Debian's own packages are covered by the automatic security updates from the security guide.
9. Back up
On the Admin tab, open Admin Tools and then Backup and Restore, and choose Schedule:
- Step 1: Who: All Users.
- Step 2: When: Now, or Cron Schedule to repeat it.
- Step 3: Where: Local saves it in
/home/admin/admin_backups. A backup that stays on the server does not help if the server is lost, so choose FTP to send it to another machine. - Step 4: What: All Data.
Choose Schedule. DirectAdmin sends a message when the backup is done.
10. The firewall
DirectAdmin installs CSF and switches it on. It allows the ports DirectAdmin's services use, such as the web, mail, FTP and DNS servers, SSH and the panel on port 2222, and blocks all other incoming traffic, over both IPv4 and IPv6. Its settings are under Extra Features and ConfigServer Security & Firewall on the Admin tab.
CSF also allows everything from the address you installed from, with a line in /etc/csf/csf.allow. If that address is shared with others, or changes, remove the line and run csf -r.
If a rule ever locks you out, the console in the client area still works. Log in there as root, and run csf -x to switch the firewall off, and csf -e to switch it on again.
Troubleshooting
You cannot reach the panel on port 2222. Some workplace and public networks block that port: try another network. If the firewall locked you out, log in on the console in the client area and run csf -x.
Creating a user fails with "That username is a reserved system name". DirectAdmin keeps some names, such as demo, for itself. Choose another one.
Visitors see a certificate for da.example.com. The site has no certificate of its own yet. Check that the domain's A and AAAA records point at the server, then request one under SSL/TLS Certificates.
Mail fails DKIM. The DKIM record is missing where the domain's DNS is managed. Copy it from DNS Management, as in step 7.